[go: up one dir, main page]

WO2016091019A1 - 一种特征数据报文的流量统计和分析方法及相应设备 - Google Patents

一种特征数据报文的流量统计和分析方法及相应设备 Download PDF

Info

Publication number
WO2016091019A1
WO2016091019A1 PCT/CN2015/092848 CN2015092848W WO2016091019A1 WO 2016091019 A1 WO2016091019 A1 WO 2016091019A1 CN 2015092848 W CN2015092848 W CN 2015092848W WO 2016091019 A1 WO2016091019 A1 WO 2016091019A1
Authority
WO
WIPO (PCT)
Prior art keywords
information
port
statistics
traffic
specified
Prior art date
Application number
PCT/CN2015/092848
Other languages
English (en)
French (fr)
Inventor
李建强
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Publication of WO2016091019A1 publication Critical patent/WO2016091019A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00Arrangements for monitoring or testing data switching networks

Definitions

  • This document relates to, but is not limited to, the field of data communication, and more particularly, to a method for traffic statistics and analysis of feature data messages, a corresponding device, and a computer readable storage medium.
  • the network traffic statistics tool is a good auxiliary means to help the network device administrator to monitor the bandwidth change of the data communication network in real time and the data traffic forwarding of each port of the network device.
  • the embodiment of the present invention provides a method for collecting and analyzing traffic statistics of feature data packets, including:
  • Each of the specified device nodes in the network collects the traffic statistics of the feature data packets on the specified port of the device node according to the configured statistics interval, and reports the specified port information and corresponding traffic statistics to the statistical analysis server.
  • the statistical analysis server visually displays the feature data message on a designated port of each designated device node according to the received specified port information and corresponding traffic statistics information. Traffic statistics analysis information and/or message forwarding path information are dynamically updated.
  • the specified port information includes the identifier information of the designated port and the identifier information of the device node where the specified port is located.
  • the traffic statistics information includes the traffic statistics value and the statistical timestamp of the feature data packet in the two directions of the sending and receiving. .
  • the method further includes: each of the designated device nodes locally records the respective designated port information and the corresponding traffic statistics information, and if the failure is reported to the statistical analysis server, the report fails when the statistical analysis server is accessible. The specified port information and the corresponding traffic statistics are reported to the statistical analysis server again.
  • the statistical analysis server visually displays the traffic statistical analysis information of the feature data packet on the designated port of each specified device node, including:
  • the statistical analysis server displays one or more of the following information related to the feature data message in a list and/or a graphic manner: information of the feature data message, information of the designated port, and two transmission and reception on the designated port.
  • the traffic statistics in the direction, the cumulative traffic value obtained by accumulating the traffic statistics, the forwarding rate on each statistical interval of the designated port, the specified port and time from the presence or absence of traffic, and the designated port from the traffic. And time, and the update time of the specified port statistics.
  • the statistical analysis server visually displays the packet forwarding path information of the feature data packet on the designated port of each specified device node, including:
  • the statistical analysis server graphically displays each specified device node and its connection relationship in the network in the message forwarding path diagram, and displays the text on the packet forwarding path map in a text or graphic manner.
  • One or more of the following information related to the feature data packet the information of the feature data packet, the information of the designated port, the traffic statistics in the two directions of the specified port, and the traffic statistics are accumulated.
  • the embodiment of the invention further provides a device node, which includes a port for sending and receiving packets and a packet statistics module deployed on the port, where:
  • the packet statistics module includes:
  • the packet statistics unit is configured to collect the traffic statistics of the feature data packets on the local port according to the configured statistics interval when the port is configured as the designated port.
  • the information reporting unit is configured to report the port information of the port and the corresponding traffic statistics to the statistical analysis server.
  • the traffic statistics collected by the packet statistics unit include: statistics statistics and statistics timestamps in the two directions in the statistics interval;
  • the port information reported by the information reporting unit includes: identifier information of the local port and identifier information of the device node where the local port is located.
  • the information reporting unit in the statistical analysis module is further configured to report the port information of the local port and the corresponding traffic statistics information to the statistical analysis module;
  • the statistical analysis module is further configured to save the received port information and the traffic statistics, and after the information reporting unit fails to report, when the statistical analysis server is accessible, the failed port information and the corresponding traffic are reported. The statistical information is reported to the statistical analysis server.
  • the embodiment of the invention further provides a statistical analysis server, comprising:
  • the information receiving module is configured to receive and save the specified port information and corresponding traffic statistics reported by each specified device node in the network;
  • the analysis and presentation module is configured to display the traffic statistical analysis information of the characteristic data packet on the designated port of each specified device node in a visual manner according to the specified port information and the corresponding traffic statistics reported by each specified device node. And/or message forwarding path information and dynamic update.
  • the specified port information received by the information receiving module includes: a port identifier of the designated port and an identifier of the device node where the specified port is located, and the received traffic statistics information includes that the feature data packet is sent and received in the two directions in the statistical interval. Traffic statistics and statistics timestamps.
  • the analysis presentation module visually displays the traffic statistical analysis information of the feature data message on the designated port of each specified device node, including:
  • the analysis presentation module displays one or more of the following information related to the feature data message in a list and/or a graphical manner: information of the feature data message, information of the designated port, and two transmission and reception at the designated port.
  • the traffic statistics in the direction the cumulative traffic value obtained by accumulating the traffic statistics, the forwarding rate on each statistical interval of the designated port, the specified port and time from the presence or absence of traffic, and the designated port from the traffic. And time, and the update time of the specified port statistics.
  • the analysis presentation module visually displays the packet forwarding path information of the feature data packet on the designated port of each specified device node, including:
  • the analysis presentation module graphically displays each specified device node and its connection relationship in the network in the message forwarding path diagram, and displays the text on the message forwarding path map in a text or graphic manner.
  • One or more of the following information related to the feature data packet the information of the feature data packet, the information of the designated port, the traffic statistics in the two directions of the specified port, and the traffic statistics are accumulated.
  • the embodiment of the present invention further provides a computer readable storage medium, which stores program instructions, and when the program instructions are executed by the processor, can implement a traffic statistics and analysis method of the feature data message provided by the embodiment of the present invention.
  • the foregoing solution can perform traffic statistics and analyze the forwarding status of the feature data packet, and can directly display the port statistical change information and the forwarding path change information of each device node of the feature data packet in the communication network, so that the network device administrator can monitor in real time. Traffic statistics and forwarding of feature data packets, or analysis of feature data packets through historical statistics over a period of time on the network Forward channel changes to help locate network faults.
  • FIG. 1 is a schematic diagram of network deployment according to an embodiment of the present invention.
  • FIG. 2 is a flowchart of a method for statistical data packet analysis and analysis according to an embodiment of the present invention
  • FIG. 3 is a schematic diagram of a packet forwarding path according to an embodiment of the present invention.
  • FIG. 4 is a block diagram of a designated device node and a statistical analysis server according to an embodiment of the present invention.
  • the feature data packet is a data packet that specifies the content of the feature.
  • the feature content can be a MAC address, an IP address, a protocol type, a communication port, or the like, or any feature content customized by the network device administrator.
  • FIG. 1 is a schematic diagram of network deployment in the embodiment, where the network includes device nodes such as switches and routers.
  • the network device administrator deploys the feature data packet statistics function on the port of the device node through the network management system to collect statistics on the traffic of the feature data packets flowing through the specified port. Generally, it is determined that the network determines the specific port of the device node associated with the monitored feature data message. If the network environment is complex and cannot be determined, you need to deploy all the ports of each communication device on the network to prevent the statistics of feature data packets from being missed.
  • the ports that are configured to perform statistics on data packets are called designated ports.
  • the device node where the specified port resides is called the designated device node.
  • the traffic statistics and analysis method of the feature data packet in this embodiment is shown in FIG. 2, and includes:
  • Step 110 Each designated device node in the network collects traffic statistics information of the feature data packet on the designated port of the local device node according to the configured statistical interval, and sends the traffic statistics information to the statistical analysis service.
  • the server reports its designated port information and corresponding traffic statistics;
  • the traffic statistics of feature data packets can be implemented by using a user-defined access control list (ACL) function. For statistics, it is not for all packets, only for the feature data packets specified by the network device administrator. That is, the data packet that enters the specified port is identified. If the feature content of the feature data packet can be matched, the traffic statistics of the data packet are collected.
  • ACL access control list
  • the traffic statistics information of the feature data packet collected on the designated port includes: a traffic statistics value and a statistical timestamp in the two directions of the feature data packet in the statistics interval.
  • the specified port information includes: the identification information of the specified port and the identifier of the device node where the specified port resides, such as the name or number of the specified port and the name or number of the device node.
  • each designated device node also records the corresponding designated port information and the corresponding traffic statistics information locally, that is, the complete traffic statistics record is saved in the device. If the failure is reported to the statistical analysis server, the specified port information and the corresponding traffic statistics that are reported to be failed are reported to the statistical analysis server again.
  • Each of the specified device nodes can display the statistical analysis result on the device, and can display one or more of the following information related to the feature data packet: the traffic statistics value in the two directions on the specified port, and the traffic statistics value. The accumulated traffic value, the forwarding rate at each statistical interval of the specified port (the value of the traffic statistics on the statistics interval divided by the time value of the statistics interval), and the update time of the specified port statistics.
  • Step 120 The statistical analysis server visually displays the traffic statistical analysis information of the feature data packet on the designated port of each specified device node according to the received designated port information and the corresponding traffic statistics information. Or the message forwards the path information and updates it dynamically.
  • the statistical analysis server visually displays the traffic statistical analysis information of the feature data packet on the designated port of each specified device node, including:
  • the statistical analysis server displays one or more of the following information related to the feature data message in a list and/or a graphic manner: information of the feature data message, information of the designated port, Specifies the traffic statistics of the port in the two directions, the cumulative value of the traffic statistics, the forwarding rate on each specified interval of the specified port, the specified port and time from the presence or absence of traffic, and the traffic from none.
  • the above flow rate from yes to no means that the flow rate statistics value changes from greater than 0 to equal to 0, and the flow cumulative value stops updating.
  • the above-mentioned flow rate from scratch refers to the case where the flow rate statistics value changes from 0 to greater than 0, and the flow rate integrated value changes from 0 to greater than 0.
  • the update time of the specified port statistics information can be the update time of the specified port traffic statistics, traffic cumulative value, or forwarding rate.
  • the statistical analysis server visually displays the packet forwarding path information of the feature data packet on the designated port of each specified device node, including:
  • the statistical analysis server graphically displays each specified device node and its connection relationship in the network in the message forwarding path diagram, and displays the text on the packet forwarding path map in a text or graphic manner.
  • One or more of the following information related to the feature data packet the information of the feature data packet, the information of the designated port, the traffic statistics in the two directions of the specified port, and the traffic statistics are accumulated.
  • the packet forwarding path map can be marked with different colors to indicate which traffic on the designated port of the network device has a sudden change from the presence or absence of the traffic, thereby dynamically and visually displaying the change process of the feature data packet forwarding path. Help network administrators monitor network anomalies and analyze network faults.
  • FIG. 3 is an example of a message forwarding path diagram, which depicts each designated device node in the network and its connection relationship. For each designated port of a specified device node, the designated port is exemplarily indicated in the figure. The traffic statistics and update time, and highlight the specified port where the mutation occurred and its traffic statistics.
  • the network in this embodiment includes at least one designated device node 10 and a statistical analysis server 20, which further includes a packet statistics module 101 and a statistical analysis module 103, where:
  • the packet statistics module 101 includes:
  • the packet statistics unit is configured to collect the traffic statistics of feature data packets on the local port based on the configured statistics interval.
  • the information reporting unit is configured to report the port information of the local port and the corresponding traffic statistics to the statistical analysis server, and optionally, to report the port information of the local port and the corresponding traffic statistics to the statistical analysis module 103.
  • the specified device node 10 further includes: a statistical analysis module 103, configured to save the received port information and the traffic statistics information, and report the failure of the information reporting unit (for example, the statistical analysis server is inaccessible) Then, when the statistical analysis server is accessible, the port information that fails to be reported and the corresponding traffic statistics are reported to the statistical analysis server.
  • a statistical analysis module 103 configured to save the received port information and the traffic statistics information, and report the failure of the information reporting unit (for example, the statistical analysis server is inaccessible) Then, when the statistical analysis server is accessible, the port information that fails to be reported and the corresponding traffic statistics are reported to the statistical analysis server.
  • the statistical analysis server 20 includes:
  • the information receiving module 201 is configured to receive and save the specified port information and corresponding traffic statistics reported by each specified device node in the network.
  • the analysis and presentation module 203 is configured to visually display the traffic statistics of the feature data packet on the designated port of each specified device node according to the specified port information and corresponding traffic statistics reported by each specified device node. Analyze information and/or message forwarding path information and dynamically update it.
  • the analysis presentation module visually displays the traffic statistical analysis information of the feature data message on a designated port of each specified device node, including: the analysis presentation module to list and/or graphic
  • the method displays one or more of the following information related to the feature data packet: the information of the feature data packet, the information of the designated port, the traffic statistics value in the two directions of sending and receiving on the designated port, and the traffic statistics.
  • the analysis and presentation module visually displays the packet forwarding path information of the feature data packet on the designated port of each specified device node, including: the packet that the analysis and presentation module is drawing In the forwarding path diagram, each specified device node in the network and its connection relationship are graphically displayed, and the following information related to the feature data packet is displayed on the packet forwarding path map in a text or graphic manner.
  • information, information, and information of the feature data message The information about the port, the traffic statistics in the two directions on the specified port, the cumulative value of the traffic statistics, the forwarding rate on each designated interval of the specified port, and the specified port from the presence to the end. And the specified port and time of time, traffic from scratch, and the update time of the specified port statistics.
  • the embodiment of the present invention further provides a computer readable storage medium, which stores program instructions, and when the program instructions are executed by the processor, can implement a traffic statistics and analysis method of the feature data message provided by the embodiment of the present invention.
  • the solution provided by the embodiment of the present invention performs traffic statistics on the feature data packet and analyzes the forwarding situation, and visually displays the port statistical change information and the forwarding path change information of each device node of the feature data packet in the communication network, so that the network device management can be performed.
  • the member monitors the traffic statistics and forwarding of feature data packets in real time, or analyzes the change of the forwarding channel of the feature data packets on the network over a period of time through historical statistics to help locate network faults.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

一种特征数据报文的流量统计和分析方法及相应设备,网络中每一个指定设备节点根据配置的统计间隔,分别在本设备节点的指定端口上采集特征数据报文的流量统计信息,并向统计分析服务器上报各自的指定端口信息和相应的流量统计信息;所述统计分析服务器根据接收的指定端口信息和相应的流量统计信息,以可视的方式展现所述特征数据报文在每一个指定设备节点的指定端口上的流量统计分析信息和/或报文转发路径信息并进行动态更新。

Description

一种特征数据报文的流量统计和分析方法及相应设备 技术领域
本文涉及但不限于数据通信领域,更具体地,涉及一种特征数据报文的流量统计和分析方法、相应设备和计算机可读存储介质。
背景技术
随着计算机及网络技术的高速发展和各种网络应用的不断涌现,基础数据通信网络的稳定性和安全性越来越重要。当数据流量在通信网络转发过程中出现异常时,需要一种有效的手段快速定位故障原因并解决问题。其中,网络流量统计工具是一种很好的辅助手段,帮助网络设备管理员实时监控数据通信网络的带宽变化情况,以及网络设备的各个端口的数据流量转发情况。
现有的数据流量统计应用,包括网络设备端口流量统计、sFlow流量采集、NetFlow流量采集等等;大部分的统计应用都是基于数据流量报文(包括报文数和字节数)的静态统计,或者是定时采样所有数据报文汇总给流量统计服务器。这些统计模式不针对具体的数据流量,无法直观地展现具体某一特征数据报文在网络中转发行为。
发明内容
以下是对本文详细描述的主题的概述,本概述并非是为了限制权利要求的保护范围。
有鉴于此,本发明实施例提供了一种特征数据报文的流量统计和分析方法,包括:
网络中每一个指定设备节点根据配置的统计间隔,分别在本设备节点的指定端口上采集特征数据报文的流量统计信息,并向统计分析服务器上报各自的指定端口信息和相应的流量统计信息;
所述统计分析服务器根据接收的指定端口信息和相应的流量统计信息,以可视的方式展现所述特征数据报文在每一个指定设备节点的指定端口上的 流量统计分析信息和/或报文转发路径信息并进行动态更新。
可选地,
所述指定端口信息包括指定端口的标识信息和指定端口所在设备节点的标识信息;所述流量统计信息包括统计间隔内所述特征数据报文在收发两个方向上的流量统计值和统计时间戳。
可选地,
所述方法还包括:每一个指定设备节点在本地记录各自的指定端口信息及相应的流量统计信息,如向所述统计分析服务器上报失败,则在所述统计分析服务器可访问时,将上报失败的指定端口信息及相应的流量统计信息再次上报给所述统计分析服务器。
可选地,
所述统计分析服务器以可视的方式展现所述特征数据报文在每一个指定设备节点的指定端口上的流量统计分析信息,包括:
所述统计分析服务器以列表和/或图形的方式展现所述特征数据报文相关的以下信息中的一种或多种:特征数据报文的信息、指定端口的信息、在指定端口收发两个方向上的流量统计值、所述流量统计值累加得到的流量累计值、在指定端口每一个统计间隔上的转发速率、流量从有到无的指定端口及时间、流量从无到有的指定端口及时间,及指定端口统计信息的更新时间。
可选地,
所述统计分析服务器以可视的方式展现所述特征数据报文在每一个指定设备节点的指定端口上的报文转发路径信息,包括:
所述统计分析服务器在绘制的报文转发路径图中,以图形的方式展现网络中的每一个指定设备节点及其连接关系,并以文字或图形的方式在所述报文转发路径图上展现所述特征数据报文相关的以下信息中的一种或多种:特征数据报文的信息、指定端口的信息、在指定端口收发两个方向上的流量统计值、所述流量统计值累加得到的流量累计值、在指定端口每一个统计间隔上的转发速率、流量从有到无的指定端口及时间、流量从无到有的指定端口及时间,及指定端口统计信息的更新时间。
本发明实施例还提供了一种设备节点,包括用于收发报文的端口和在端口上部署的报文统计模块,其中:
所述报文统计模块包括:
报文统计单元,设置为在本端口被配置为指定端口时,根据配置的统计间隔,在本端口采集特征数据报文的流量统计信息;
信息上报单元,设置为将本端口的端口信息及相应的流量统计信息上报统计分析服务器。
可选地,
所述报文统计单元采集的流量统计信息包括:统计间隔内收发两个方向上的流量统计值和统计时间戳;
所述信息上报单元上报的端口信息包括:本端口的标识信息及本端口所在设备节点的标识信息。
可选地,
其中,所述统计分析模块中的所述信息上报单元还设置为向所述统计分析模块上报本端口的端口信息和相应的流量统计信息;
所述统计分析模块还设置为保存接收到的端口信息和流量统计信息,及在所述信息上报单元上报失败后,在所述统计分析服务器可访问时,将上报失败的端口信息和相应的流量统计信息上报给所述统计分析服务器。
本发明实施例还提供了一种统计分析服务器,包括:
信息接收模块,设置为接收网络中每一个指定设备节点上报的指定端口信息和相应的流量统计信息并保存;
分析展现模块,设置根据每一个指定设备节点上报的指定端口信息和相应的流量统计信息,以可视的方式展现所述特征数据报文在每一个指定设备节点的指定端口上的流量统计分析信息和/或报文转发路径信息并进行动态更新。
可选地,
所述信息接收模块接收的所述指定端口信息包括:指定端口的端口标识和指定端口所在设备节点的标识,接收的所述流量统计信息包括统计间隔内所述特征数据报文在收发两个方向上的流量统计值和统计时间戳。
可选地,
所述分析展现模块以可视的方式展现所述特征数据报文在每一个指定设备节点的指定端口上的流量统计分析信息,包括:
所述分析展现模块以列表和/或图形的方式展现所述特征数据报文相关的以下信息中的一种或多种:特征数据报文的信息、指定端口的信息、在指定端口收发两个方向上的流量统计值、所述流量统计值累加得到的流量累计值、在指定端口每一个统计间隔上的转发速率、流量从有到无的指定端口及时间、流量从无到有的指定端口及时间,及指定端口统计信息的更新时间。
可选地,
所述分析展现模块以可视的方式展现所述特征数据报文在每一个指定设备节点的指定端口上的报文转发路径信息,包括:
所述分析展现模块在绘制的报文转发路径图中,以图形的方式展现网络中的每一个指定设备节点及其连接关系,并以文字或图形的方式在所述报文转发路径图上展现所述特征数据报文相关的以下信息中的一种或多种:特征数据报文的信息、指定端口的信息、在指定端口收发两个方向上的流量统计值、所述流量统计值累加得到的流量累计值、在指定端口每一个统计间隔上的转发速率、流量从有到无的指定端口及时间、流量从无到有的指定端口及时间,及指定端口统计信息的更新时间。
本发明实施例还提供一种计算机可读存储介质,存储有程序指令,当该程序指令被处理器执行时可实现本发明实施例所提供的一种特征数据报文的流量统计和分析方法。
上述方案可针对特征数据报文进行流量统计并分析转发情况,可以直观展现特征数据报文在通信网络中每一个设备节点的端口统计变化信息和转发路径变化信息,使网络设备管理员可以实时监控特征数据报文的流量统计及转发情况,或通过历史统计数据分析特征数据报文在一段时间内在网络上的 转发通道变化情况,协助定位网络故障。
在阅读并理解了附图和详细描述后,可以明白其他方面。
附图概述
图1是本发明实施例的网络部署示意图;
图2是本发明实施例特征数据报文统计和分析方法的流程图;
图3是本发明实施例报文转发路径的示意图;
图4是本发明实施例指定设备节点和统计分析服务器的模块图。
本发明的较佳实施方式
下文中将结合附图对本发明的实施例进行详细说明。需要说明的是,在不冲突的情况下,本申请中的实施例及实施例中的特征可以相互任意组合。
特征数据报文即包含指定特征内容的数据报文,这些特征内容可以是MAC地址、IP地址、协议类型、通信端口等,也可以是网络设备管理员自定义的任意特征内容。
图1是本实施例的网络部署示意图,网络中包括交换机、路由器等设备节点。网络设备管理员通过网管系统在设备节点的端口上部署特征数据报文统计功能,以对流经指定端口的特征数据报文的流量进行统计。一般地,在网络中判定和被监测特征数据报文相关的设备节点的特定端口上部署即可。如果网络环境比较复杂,无法明显判定,则需要在网络中的每一台通信设备的所有端口部署,防止特征数据报文统计遗漏。文中,这些被部署了要执行数据报文统计的端口称为指定端口,指定端口所在的设备节点称为指定设备节点。
本实施例特征数据报文的流量统计和分析方法图2所示,包括:
步骤110,网络中每一个指定设备节点根据配置的统计间隔,分别在本设备节点的指定端口上采集特征数据报文的流量统计信息,并向统计分析服 务器上报各自的指定端口信息和相应的流量统计信息;
可以通过网管系统配置特征数据报文的特征内容和统计间隔,也可以选择清除网络内的所有设备或指定设备上的特征数据报文统计值,重新开始统计特征报文。
特征数据报文的流量统计可以采用用户自定义访问控制列表(ACL)功能实现。统计时,不针对所有报文,只针对网络设备管理员指定的特征数据报文。即对进入指定端口的数据报文进行识别,如果可以匹配到特征数据报文的特征内容,才对该数据报文进行流量统计。
可选地,在指定端口上采集的特征数据报文的流量统计信息包括:统计间隔内所述特征数据报文在收发两个方向上的流量统计值和统计时间戳。指定端口信息包括:指定端口的标识信息和指定端口所在设备节点的标识信息,如指定端口的名称或编号及所在设备节点的名称或编号。
可选地,每一个指定设备节点还在本地记录各自的指定端口信息及相应的流量统计信息,即在本设备保存完整的流量统计记录。如果向所述统计分析服务器上报失败,则在所述统计分析服务器可访问时,将上报失败的指定端口信息及相应的流量统计信息再次上报给所述统计分析服务器。每一个指定设备节点可以在本设备展示统计分析结果,可以显示特征数据报文相关的以下信息中的一种或多种:在指定端口收发两个方向上的流量统计值、所述流量统计值累加得到的流量累计值、在指定端口每一个统计间隔上的转发速率(统计间隔上流量统计值的变化值除以该统计间隔的时间值得到)及指定端口统计信息的更新时间。
步骤120,所述统计分析服务器根据接收的指定端口信息和相应的流量统计信息,以可视的方式展现所述特征数据报文在每一个指定设备节点的指定端口上的流量统计分析信息和/或报文转发路径信息并进行动态更新。
可选地,所述统计分析服务器以可视的方式展现所述特征数据报文在每一个指定设备节点的指定端口上的流量统计分析信息,包括:
所述统计分析服务器以列表和/或图形的方式展现所述特征数据报文相关的以下信息中的一种或多种:特征数据报文的信息、指定端口的信息、在 指定端口收发两个方向上的流量统计值、所述流量统计值累加得到的流量累计值、在指定端口每一个统计间隔上的转发速率、流量从有到无的指定端口及时间、流量从无到有的指定端口及时间,及指定端口统计信息的更新时间。上述流量从有到无是指流量统计值从大于0变为等于0,流量累计值停止更新的情况。上述流量从无到有是指流量统计值从0变为大于0,流量累计值从0变为大于0的情况。上述指定端口统计信息的更新时间可以为指定端口流量统计值、流量累计值或转发速率的更新时间。
可选地,所述统计分析服务器以可视的方式展现所述特征数据报文在每一个指定设备节点的指定端口上的报文转发路径信息,包括:
所述统计分析服务器在绘制的报文转发路径图中,以图形的方式展现网络中的每一个指定设备节点及其连接关系,并以文字或图形的方式在所述报文转发路径图上展现所述特征数据报文相关的以下信息中的一种或多种:特征数据报文的信息、指定端口的信息、在指定端口收发两个方向上的流量统计值、所述流量统计值累加得到的流量累计值、在指定端口每一个统计间隔上的转发速率、流量从有到无的指定端口及时间、流量从无到有的指定端口及时间,及指定端口统计信息的更新时间。报文转发路径图上可以用不同的颜色重点标示出哪些网络设备的指定端口上发生流量从有到无或有无到有的突变,由此来动态直观展示特征数据报文转发路径变化过程,帮助网络管理员监控网络异常状态和分析定位网络故障。
图3是报文转发路径图的一个示例,图中绘出了网络中每一个指定设备节点及其连接关系,对每一个指定设备节点的指定端口,图中示例性的标示出了该指定端口的流量统计值及更新时间,并突出显示了发生突变的指定端口及其流量统计值。
如图4所示,本实施例的网络包括至少一个指定设备节点10和一个统计分析服务器20,该指定设备节点10又包括报文统计模块101和统计分析模块103,其中:
所述报文统计模块101包括:
报文统计单元,设置为在本端口被配置为指定端口时,根据配置的统计间隔,在本端口采集特征数据报文的流量统计信息。
信息上报单元,设置为将本端口的端口信息及相应的流量统计信息上报统计分析服务器,可选地,还设置为向统计分析模块103上报本端口的端口信息和相应的流量统计信息。
可选地,所述指定设备节点10还包括:统计分析模块103,设置为保存接收到的端口信息和流量统计信息,及在所述信息上报单元上报失败(如统计分析服务器不可访问等原因)后,在所述统计分析服务器可访问时,将上报失败的端口信息和相应的流量统计信息上报给所述统计分析服务器。
所述统计分析服务器20包括:
信息接收模块201,设置为接收网络中每一个指定设备节点上报的指定端口信息和相应的流量统计信息并保存。
分析展现模块203,设置为根据每一个指定设备节点上报的指定端口信息和相应的流量统计信息,以可视的方式展现所述特征数据报文在每一个指定设备节点的指定端口上的流量统计分析信息和/或报文转发路径信息并进行动态更新。
可选地,所述分析展现模块以可视的方式展现所述特征数据报文在每一个指定设备节点的指定端口上的流量统计分析信息,包括:所述分析展现模块以列表和/或图形的方式展现所述特征数据报文相关的以下信息中的一种或多种:特征数据报文的信息、指定端口的信息、在指定端口收发两个方向上的流量统计值、所述流量统计值累加得到的流量累计值、在指定端口每一个统计间隔上的转发速率、流量从有到无的指定端口及时间、流量从无到有的指定端口及时间,及指定端口统计信息的更新时间。
可选地,所述分析展现模块以可视的方式展现所述特征数据报文在每一个指定设备节点的指定端口上的报文转发路径信息,包括:所述分析展现模块在绘制的报文转发路径图中,以图形的方式展现网络中的每一个指定设备节点及其连接关系,并以文字或图形的方式在所述报文转发路径图上展现所述特征数据报文相关的以下信息中的一种或多种:特征数据报文的信息、指 定端口的信息、在指定端口收发两个方向上的流量统计值、所述流量统计值累加得到的流量累计值、在指定端口每一个统计间隔上的转发速率、流量从有到无的指定端口及时间、流量从无到有的指定端口及时间,及指定端口统计信息的更新时间。
本发明实施例还提供一种计算机可读存储介质,存储有程序指令,当该程序指令被处理器执行时可实现本发明实施例所提供的一种特征数据报文的流量统计和分析方法。
本领域普通技术人员可以理解上述方法中的全部或部分步骤可通过程序来指令相关硬件完成,所述程序可以存储于计算机可读存储介质中,如只读存储器、磁盘或光盘等。可选地,上述实施例的全部或部分步骤也可以使用一个或多个集成电路来实现,相应地,上述实施例中的各模块/单元可以采用硬件的形式实现,也可以采用软件功能模块的形式实现。本发明不限制于任何特定形式的硬件和软件的结合。
工业实用性
本发明实施例提供的方案针对特征数据报文进行流量统计并分析转发情况,直观展现特征数据报文在通信网络中每一个设备节点的端口统计变化信息和转发路径变化信息,可以使网络设备管理员实时监控特征数据报文的流量统计及转发情况,或通过历史统计数据分析特征数据报文在一段时间内在网络上的转发通道变化情况,协助定位网络故障。

Claims (13)

  1. 一种特征数据报文的流量统计和分析方法,包括:
    网络中每一个指定设备节点根据配置的统计间隔,分别在本设备节点的指定端口上采集特征数据报文的流量统计信息,并向统计分析服务器上报各自的指定端口信息和相应的流量统计信息;
    所述统计分析服务器根据接收的指定端口信息和相应的流量统计信息,以可视的方式展现所述特征数据报文在每一个指定设备节点的指定端口上的流量统计分析信息和/或报文转发路径信息并进行动态更新。
  2. 如权利要求1所述的方法,其中,
    所述指定端口信息包括:指定端口的标识信息和指定端口所在设备节点的标识信息;所述流量统计信息包括:统计间隔内所述特征数据报文在收发两个方向上的流量统计值和统计时间戳。
  3. 如权利要求1所述的方法,还包括:
    每一个指定设备节点在本地记录各自的指定端口信息及相应的流量统计信息,如向所述统计分析服务器上报失败,则在所述统计分析服务器可访问时,将上报失败的指定端口信息及相应的流量统计信息再次上报给所述统计分析服务器。
  4. 如权利要求2所述的方法,其中,
    所述统计分析服务器以可视的方式展现所述特征数据报文在每一个指定设备节点的指定端口上的流量统计分析信息,包括:
    所述统计分析服务器以列表和/或图形的方式展现所述特征数据报文相关的以下信息中的一种或多种:特征数据报文的信息、指定端口的信息、在指定端口收发两个方向上的流量统计值、所述流量统计值累加得到的流量累计值、在指定端口每一个统计间隔上的转发速率、流量从有到无的指定端口及时间、流量从无到有的指定端口及时间,及指定端口统计信息的更新时间。
  5. 如权利要求2或4所述的方法,其中,
    所述统计分析服务器以可视的方式展现所述特征数据报文在每一个指定设备节点的指定端口上的报文转发路径信息,包括:
    所述统计分析服务器在绘制的报文转发路径图中,以图形的方式展现网络中的每一个指定设备节点及其连接关系,并以文字或图形的方式在所述报文转发路径图上展现所述特征数据报文相关的以下信息中的一种或多种:特征数据报文的信息、指定端口的信息、在指定端口收发两个方向上的流量统计值、所述流量统计值累加得到的流量累计值、在指定端口每一个统计间隔上的转发速率、流量从有到无的指定端口及时间、流量从无到有的指定端口及时间,及指定端口统计信息的更新时间。
  6. 一种设备节点,包括用于收发报文的端口,还包括在端口上部署的报文统计模块,其中:
    所述报文统计模块包括:
    报文统计单元,设置为在本端口被配置为指定端口时,根据配置的统计间隔,在本端口采集特征数据报文的流量统计信息;
    信息上报单元,设置为将本端口的端口信息及相应的流量统计信息上报统计分析服务器。
  7. 如权利要求6所述的设备节点,其中,
    所述报文统计单元采集的流量统计信息包括:统计间隔内收发两个方向上的流量统计值和统计时间戳;
    所述信息上报单元上报的端口信息包括:本端口的标识信息及本端口所在设备节点的标识信息。
  8. 如权利要求6或7所述的设备节点,其中,
    所述设备节点还包括统计分析模块;
    所述信息上报单元还设置为向所述统计分析模块上报本端口的端口信息和相应的流量统计信息;
    所述统计分析模块设置为保存接收到的端口信息和流量统计信息,及在所述信息上报单元上报失败后,在所述统计分析服务器可访问时,将上报失 败的端口信息和相应的流量统计信息上报给所述统计分析服务器。
  9. 一种统计分析服务器,包括:
    信息接收模块,设置为接收网络中每一个指定设备节点上报的指定端口信息和相应的流量统计信息并保存;
    分析展现模块,设置为根据每一个指定设备节点上报的指定端口信息和相应的流量统计信息,以可视的方式展现所述特征数据报文在每一个指定设备节点的指定端口上的流量统计分析信息和/或报文转发路径信息并进行动态更新。
  10. 如权利要求9所述的统计分析服务器,其中,
    所述信息接收模块接收的所述指定端口信息包括:指定端口的端口标识和指定端口所在设备节点的标识;接收的所述流量统计信息包括:统计间隔内所述特征数据报文在收发两个方向上的流量统计值和统计时间戳。
  11. 如权利要求10所述的统计分析服务器,其中,
    所述分析展现模块以可视的方式展现所述特征数据报文在每一个指定设备节点的指定端口上的流量统计分析信息,包括:
    所述分析展现模块以列表和/或图形的方式展现所述特征数据报文相关的以下信息中的一种或多种:特征数据报文的信息、指定端口的信息、在指定端口收发两个方向上的流量统计值、所述流量统计值累加得到的流量累计值、在指定端口每一个统计间隔上的转发速率、流量从有到无的指定端口及时间、流量从无到有的指定端口及时间,及指定端口统计信息的更新时间。
  12. 如权利要求10或11所述的统计分析服务器,其中,
    所述分析展现模块以可视的方式展现所述特征数据报文在每一个指定设备节点的指定端口上的报文转发路径信息,包括:
    所述分析展现模块在绘制的报文转发路径图中,以图形的方式展现网络中的每一个指定设备节点及其连接关系,并以文字或图形的方式在所述报文转发路径图上展现所述特征数据报文相关的以下信息中的一种或多种:特征 数据报文的信息、指定端口的信息、在指定端口收发两个方向上的流量统计值、所述流量统计值累加得到的流量累计值、在指定端口每一个统计间隔上的转发速率、流量从有到无的指定端口及时间、流量从无到有的指定端口及时间,及指定端口统计信息的更新时间。
  13. 一种计算机可读存储介质,存储有程序指令,当该程序指令被处理器执行时实现权利要求1-5任一项所述的方法。
PCT/CN2015/092848 2014-12-10 2015-10-26 一种特征数据报文的流量统计和分析方法及相应设备 WO2016091019A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201410758217.9 2014-12-10
CN201410758217.9A CN105743726A (zh) 2014-12-10 2014-12-10 一种特征数据报文的流量统计和分析方法及相应设备

Publications (1)

Publication Number Publication Date
WO2016091019A1 true WO2016091019A1 (zh) 2016-06-16

Family

ID=56106650

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2015/092848 WO2016091019A1 (zh) 2014-12-10 2015-10-26 一种特征数据报文的流量统计和分析方法及相应设备

Country Status (2)

Country Link
CN (1) CN105743726A (zh)
WO (1) WO2016091019A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN118646682A (zh) * 2024-08-08 2024-09-13 芯云晟(杭州)电子科技有限公司 多端口多通道报文分类统计装置及方法

Families Citing this family (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109474447B (zh) * 2017-09-07 2022-04-12 北京京东尚科信息技术有限公司 用于实时监控系统的告警方法和装置
CN109450656A (zh) * 2018-12-30 2019-03-08 北京世纪互联宽带数据中心有限公司 一种计费流量图生成方法及装置
CN110351138A (zh) * 2019-07-11 2019-10-18 中国工商银行股份有限公司 应用于联机事务处理系统的故障定位方法和系统
CN113347055A (zh) * 2021-04-29 2021-09-03 海南视联通信技术有限公司 监控流量速率的方法及装置、计算机可读存储介质

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102868553A (zh) * 2012-08-28 2013-01-09 华为技术有限公司 故障定位方法及相关设备
CN102946330A (zh) * 2012-09-29 2013-02-27 华为技术有限公司 网络丢包测量方法、装置和系统
CN103580959A (zh) * 2013-11-15 2014-02-12 大连梯耐德网络技术有限公司 一种分布式统计上报的实现方法
US20140269319A1 (en) * 2013-03-15 2014-09-18 International Business Machines Corporation Network per-flow rate limiting

Family Cites Families (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN100531146C (zh) * 2007-01-25 2009-08-19 华为技术有限公司 基于流转发的更新流转发表项内容的方法及设备
CN101635730B (zh) * 2009-08-28 2012-05-02 深圳市永达电子股份有限公司 中小企业内网信息安全托管方法与系统
CN102148703A (zh) * 2011-01-19 2011-08-10 武汉迈威光电技术有限公司 一种交换机网管拓扑图实现算法
CN103298010B (zh) * 2013-05-20 2016-03-09 华为技术有限公司 一种网络链路状况显示方法和装置

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102868553A (zh) * 2012-08-28 2013-01-09 华为技术有限公司 故障定位方法及相关设备
CN102946330A (zh) * 2012-09-29 2013-02-27 华为技术有限公司 网络丢包测量方法、装置和系统
US20140269319A1 (en) * 2013-03-15 2014-09-18 International Business Machines Corporation Network per-flow rate limiting
CN103580959A (zh) * 2013-11-15 2014-02-12 大连梯耐德网络技术有限公司 一种分布式统计上报的实现方法

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN118646682A (zh) * 2024-08-08 2024-09-13 芯云晟(杭州)电子科技有限公司 多端口多通道报文分类统计装置及方法

Also Published As

Publication number Publication date
CN105743726A (zh) 2016-07-06

Similar Documents

Publication Publication Date Title
US11038744B2 (en) Triggered in-band operations, administration, and maintenance in a network environment
US8811193B2 (en) Network path discovery and analysis
US7483379B2 (en) Passive network monitoring system
EP2529570B1 (en) Tracing mobile sessions
US8767584B2 (en) Method and apparatus for analyzing mobile services delivery
US20160294603A1 (en) Dynamic configuration of entity polling using network topology and entity status
WO2016091019A1 (zh) 一种特征数据报文的流量统计和分析方法及相应设备
US8542576B2 (en) Method and apparatus for auditing 4G mobility networks
US20240113944A1 (en) Determining an organizational level network topology
US20240259286A1 (en) Per-application network performance analysis
Vuletić et al. Localization of network service performance degradation in multi-tenant networks
JP6733923B1 (ja) ネットワーク管理システム、ネットワーク管理方法およびネットワーク管理プログラム
CN105207945A (zh) 一种基于二、三层报文地址的端口镜像方法
EP4395265A1 (en) Detecting wired client stuck
CN112312228B (zh) 媒体传输质量指标检测方法、装置及存储介质
Draai et al. Implementing perfSONAR in the South African National Research and Education Network
Kim et al. Real-time multicast network monitoring
JP2008211415A (ja) パケット制御命令管理方法

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 15868208

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 15868208

Country of ref document: EP

Kind code of ref document: A1